securityUmbrella
ActivePublic

Recent Activity

Jul 7 2017

tz closed D11515: lang/php70: Update to 7.0.21 by committing rP445231: Update PHP 7 from 7.0.20 to 7.0.21.
Jul 7 2017, 9:58 AM · security
tz accepted D11515: lang/php70: Update to 7.0.21.
Jul 7 2017, 9:57 AM · security
tz closed D11516: lang/php71: Update to 7.1.7.

Was already committed in r445228.

Jul 7 2017, 9:46 AM · security
tz accepted D11516: lang/php71: Update to 7.1.7.
Jul 7 2017, 9:45 AM · security
i.dani_outlook.com created D11516: lang/php71: Update to 7.1.7.
Jul 7 2017, 9:37 AM · security
i.dani_outlook.com created D11515: lang/php70: Update to 7.0.21.
Jul 7 2017, 9:34 AM · security

Jun 30 2017

lwhsu changed the visibility for security.
Jun 30 2017, 6:40 PM

Jun 11 2017

badfilemagic_gmail.com added a watcher for security: badfilemagic_gmail.com.
Jun 11 2017, 3:31 PM

Mar 22 2016

lattera-gmail.com added a watcher for security: lattera-gmail.com.
Mar 22 2016, 12:22 AM

Jan 19 2016

bapt closed D4771: libfetch: test for /etc/ssl/cert.pem existence to avoid masking SSL_CA_CERT_PATH.
Jan 19 2016, 3:04 PM · security
bapt accepted D4771: libfetch: test for /etc/ssl/cert.pem existence to avoid masking SSL_CA_CERT_PATH.

As been committed as rS294326 (discussed with des)

Jan 19 2016, 3:04 PM · security

Jan 4 2016

john_saltant.com updated the test plan for D4771: libfetch: test for /etc/ssl/cert.pem existence to avoid masking SSL_CA_CERT_PATH.
Jan 4 2016, 12:55 PM · security

Jan 3 2016

john_saltant.com retitled D4771: libfetch: test for /etc/ssl/cert.pem existence to avoid masking SSL_CA_CERT_PATH from to libfetch: test for /etc/ssl/cert.pem existence to avoid masking SSL_CA_CERT_PATH.
Jan 3 2016, 11:44 PM · security

Oct 22 2015

koobs added a comment to D3463: Adopt higher level of stack protection..

Apologies, I intended to Commandeer -> Close.

Oct 22 2015, 9:57 AM · security
koobs commandeered D3463: Adopt higher level of stack protection..
Oct 22 2015, 9:56 AM · security
koobs updated subscribers of D3463: Adopt higher level of stack protection..
Oct 22 2015, 9:49 AM · security

Oct 8 2015

op added a dependent revision for D3463: Adopt higher level of stack protection.: D3848: follow up the latest stack-protector-strong changes in libc too.
Oct 8 2015, 8:52 PM · security
pfg abandoned D3463: Adopt higher level of stack protection..

This is already in the tree (apparently no one approved it though).

Oct 8 2015, 3:12 PM · security

Oct 4 2015

pfg added a comment to D3463: Adopt higher level of stack protection..

Committed as r288669.

Oct 4 2015, 7:11 PM · security
pfg updated the test plan for D3463: Adopt higher level of stack protection..
Oct 4 2015, 7:10 PM · security

Oct 3 2015

pfg added a comment to D3463: Adopt higher level of stack protection..

Results from exp-run (PR 2013394) are out:


Exp-run results on head i386:
http://package23.nyi.freebsd.org/jail.html?mastername=headi386PR203394-default

Oct 3 2015, 5:56 PM · security

Sep 28 2015

pfg added a comment to D3463: Adopt higher level of stack protection..

Peter Holm has kindly provided some testing:

Sep 28 2015, 2:37 PM · security

Sep 27 2015

sunpoet updated subscribers of D3463: Adopt higher level of stack protection..
Sep 27 2015, 4:25 PM · security

Sep 26 2015

pfg added a comment to D3463: Adopt higher level of stack protection..

...

Will it be possible that you can provide some basic test data, for instance, a few world stone runs on memory disk, and see how exactly the impact would be? It would be easier to convince people when you have first hand data, and although we know others have already do some testing, it's important to know if the same applies on FreeBSD because it's likely that the experiments were not on FreeBSD, and the result may be different.

Sep 26 2015, 3:17 AM · security

Sep 25 2015

delphij added a comment to D3463: Adopt higher level of stack protection..

I'll patch my laptop and have started a clean build so I'll see if there would be visible performance/other impact after running with it for a few days.

Sep 25 2015, 7:58 PM · security
milios_ccsys.com updated subscribers of D3463: Adopt higher level of stack protection..
Sep 25 2015, 9:30 AM · security

Aug 29 2015

pfg added a comment to D3463: Adopt higher level of stack protection..
Aug 29 2015, 7:53 PM · security

Aug 28 2015

pfg added a comment to D3463: Adopt higher level of stack protection..
Aug 28 2015, 2:57 PM · security

Aug 27 2015

bdrewery added a comment to D3463: Adopt higher level of stack protection..

+1

Aug 27 2015, 6:22 PM · security
pfg added a reviewer for D3463: Adopt higher level of stack protection.: jlh.
Aug 27 2015, 4:07 PM · security

Aug 23 2015

pfg added a comment to D3463: Adopt higher level of stack protection..
In D3463#70669, @imp wrote:

What's the performance impact?

Aug 23 2015, 3:26 PM · security
op added a comment to D3463: Adopt higher level of stack protection..

We should investigate that the -fstack-protector-strong triggers the same as -fstack-protector-all:

Aug 23 2015, 12:07 PM · security
op added a comment to D3463: Adopt higher level of stack protection..
Aug 23 2015, 12:03 PM · security
imp requested changes to D3463: Adopt higher level of stack protection..

What's the performance impact?

Aug 23 2015, 3:25 AM · security
pfg added a reviewer for D3463: Adopt higher level of stack protection.: secteam.
Aug 23 2015, 3:22 AM · security

Jul 15 2015

jmg added a member for security: jmg.
Jul 15 2015, 5:44 AM

Jul 12 2015

markm added a member for security: markm.
Jul 12 2015, 6:32 PM